Frequency
8
occurrences
First Seen
March 31, 2026
Last Seen
August 21, 2026
Related Threat Clusters
-
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Operation TrueChaos: Exploitation of TrueConf Zero-Day Vulnerability
In early 2026, a series of targeted attacks named Operation TrueChaos exploited a zero-day vulnerability in TrueConf software, tracked as CVE-2026-3502, which allows attackers to execute arbitrary files on connected…
5 articles · Updated April 1, 2026 -
Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts
In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…
9 articles · Updated April 1, 2026
Recent Intelligence Reports
- CISA orders feds to patch actively exploited TrueConf Server flaws — Bleepingcomputer · August 21, 2026
- CISA orders feds to patch actively exploited TrueConf Server flaws — Bleepingcomputer · August 21, 2026
- Hackers breach TrueConf to trojanize client installers with backdoors — Bleepingcomputer · August 8, 2026
- Hackers breach TrueConf to trojanize client installers with backdoors — Bleepingcomputer · August 8, 2026
- TrueConf zero — Feeds2.Feedburner · April 2, 2026
- Hackers exploit TrueConf zero — Bleepingcomputer · April 1, 2026
- Risky Bulletin: Iranian password sprays came first, then came the missiles — News.Risky.Biz · April 1, 2026
- Operation TrueChaos: 0 — Research.Checkpoint · March 31, 2026